CVE-2026-0128
published 2026-06-16CVE-2026-0128: In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with…
PriorityP334medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.18%
8.0th percentile
In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow.
ghsa_unreviewed·2026-06-16
CVE-2026-0128 In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow.
In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
VulDB
Google Android decodeRtcpFbPacket integer overflow
vuldb·2026-06-16
CVE-2026-0128 [CRITICAL] Google Android decodeRtcpFbPacket integer overflow
A vulnerability was found in Google Android. It has been rated as critical. This vulnerability affects the function RtcpFbPacket::decodeRtcpFbPacket. Performing a manipulation results in integer overflow.
This vulnerability is known as CVE-2026-0128. Remote exploitation of the attack is possible. No exploit is available.
No detection rules found.
No public exploits indexed.
2026-06-16
Published